CVE-2026-35616CRITICAL 9.8CISA KEVEPSS p99.8%

CVE-2026-35616Fortinet FortiClient EMS Improper Access Control Vulnerability

Fortinet / FortiClient EMS

Description

Fortinet FortiClient EMS contains an improper access control vulnerability that may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS88.50% probability of exploitation · percentile 99.8% · 2026-06-19T12:03:05Z
Published2026-04-04
Last modified2026-04-06

CISA KEV entry

Added to KEV: 2026-04-06

Underlying weaknesses· 1

CWE-284

References

  1. https://fortiguard.fortinet.com/psirt/FG-IR-26-099
  2. https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35616

1

TypeTargetConfidenceTier
WeaknessImproper Access Controlcwe-2840%live

(incoming)1

TypeTargetConfidenceTier
KEVEntryFortinet FortiClient EMS Improper Access Control Vulnerabilitykev-cve-2026-356160%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
Fortinet FortiClient EMS SQL Injection Vulnerability
CVE
CVE-2025-22256
CVE
CVE-2022-40684
CVE
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
CVE
CVE-2026-49938
CVE
CVE-2026-44277
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.